The news
The CenterPoint Energy data breach, disclosed on September 14, exposed personal information of some customers of the Houston-based utility (CNP), after a hacker claimed to have pulled 7.49 million records through a poorly protected public API.
In a Form 8-K filed under Item 8.01, the section for other events, CenterPoint Energy said it learned in September of an online post by a third party claiming to hold a data set of customer information. The company said it activated its incident response protocols, brought in outside cybersecurity experts and informed law enforcement and certain regulators.
The filing states that an unauthorized third party obtained personal information relating to a portion of customers through one of the company's external-facing systems. Electric and gas delivery was not affected. CenterPoint said it does not believe a material impact on its financial condition or results is reasonably likely, and that it expects cybersecurity insurance to offset some incident costs. It plans to notify affected customers and regulators as the law requires.
The attacker, who uses the handle 4d722e4d656f77, told BleepingComputer the data includes names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers. The hacker said the records came from cycling through millions of customer IDs on a public CenterPoint API that had no effective rate limiting, meaning no cap on how many requests one client can make, and no web application firewall. Help Net Security reported the attacker also listed email addresses and driver's license numbers. CenterPoint has not confirmed the record count or the fields.
CenterPoint serves about 7 million metered customers in Indiana, Minnesota, Ohio and Texas, according to BleepingComputer, which also reported that the attacker leaked the data after saying the company ignored their messages. Several proposed class actions have been filed in federal court alleging the breach took place between August 17 and September 1. Asked for more detail, the company told Indiana station 14 News that its filing speaks for itself.
The numbers
- Records claimed by the attacker (unverified)
- 7.49 million
- CenterPoint metered customers
- About 7 million
- Breach window alleged in lawsuits
- Aug 17 – Sept 1, 2026
- Form 8-K filed
- Sept 14, 2026
Why CEOs should care
For CISOs and engineering leaders, the claimed method is the lesson. If the attacker's account is accurate, no malware or stolen password was needed, only a public API that answered every request for a customer ID. Ask your teams for an inventory of every customer-facing API that returns personal data, whether record IDs are sequential or guessable, what rate limits and bot controls sit in front of those APIs, and whether anyone would notice millions of lookups spread over days or weeks.
For CFOs and boards, CenterPoint shows that an immateriality finding does not cap legal exposure. The company said that, as of its filing, a material financial effect was not reasonably likely, and it pointed to insurance, yet proposed class actions had been filed in federal courts by September 15, according to BleepingComputer. Finance chiefs should confirm what their cyber policy pays for class-action defense, notification and credit monitoring, and boards should ask who decides how an incident is disclosed and on what evidence.
For buyers of billing, portal and customer-service software, the same question applies to vendors. Ask suppliers that expose your customer data through APIs to show their authentication, rate-limiting and abuse-monitoring controls, and write those expectations into contracts.
The bigger picture
According to BleepingComputer, the attacker says the data was leaked after CenterPoint ignored its messages; the outlet did not report any ransom demand. For utilities, the case also shows that the most immediate cyber risk may sit in customer systems rather than the grid itself. The company stressed that power and gas service never wavered, but the reputational and legal costs attach to the customer data.
The case also shows that disclosure now runs on two tracks: a formal filing that speaks carefully about materiality, and a public narrative shaped by the attacker's posts and by plaintiffs' lawyers. Companies need a communications plan for both, prepared before an incident rather than during one.
What’s next
Watch for CenterPoint's customer notification letters and state regulator filings, which should show how many people the company itself counts as affected, and for any updated SEC filing if its view of the financial impact changes. The federal lawsuits may also be consolidated, which would set the pace for any settlement talks.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





